Impact
Co‑Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress contains a stored cross‑site scripting flaw that allows an authenticated user with Author‑level access or higher to insert arbitrary JavaScript into the profile_fields_user_email_value_prefix parameter. The value is saved in the database and rendered in the author box; when another user views a page that includes the author box and follows a link, the malicious payload executes in that visitor’s browser, potentially delivering unwanted content or effects.
Affected Systems
WordPress sites that have the PublishPress Authors plugin version 4.15.0 or earlier installed and with the author box module enabled are affected. Any account that has Author or higher permissions on the site can become an attacker.
Risk and Exploitability
The vulnerability carries a CVSS base score of 5.4, representing moderate severity. Its EPSS score is 0.00138, indicating a very low probability of exploitation. It is not listed in CISA KEV. Exploitation requires an authenticated user with Author-level access or higher to modify the vulnerable field; the malicious script is then stored and rendered in the author box, reaching any site visitor who views that page.
OpenCVE Enrichment